TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Artificial Intelligence

OpenAI Confirms Hack Linked to TanStack Attack

Akinola Ajibola by Akinola Ajibola
May 14, 2026
in Artificial Intelligence, Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • It has been discovered that hackers took control of multiple open-source projects that were utilised by numerous businesses earlier this week and released updates intended to...
  • This is claimed to be the most recent of several recent attacks on software engineers and their projects that are referred to as “supply chain” attacks.
  • OpenAI acknowledged on Wednesday that this hack had greatly “impacted” the devices of two workers.

It has been discovered that hackers took control of multiple open-source projects that were utilised by numerous businesses earlier this week and released updates intended to propagate malware. This is claimed to be the most recent of several recent attacks on software engineers and their projects that are referred to as “supply chain” attacks.

OpenAI acknowledged on Wednesday that this hack had greatly “impacted” the devices of two workers. However, following an inquiry, the business stated in a blog post that it had “no evidence that our production systems or intellectual property were compromised in any way, that our software was altered, or that OpenAI user data was accessed.”

A data breach brought on by a software supply chain attack that has been verified by OpenAI. The popular open-source web application library TanStack was taken over by hackers, which led to the event. OpenAI claims there is no proof that customer user data, production systems, or fundamental AI intellectual property were accessed or compromised, despite the attackers’ successful theft of internal credential material from particular code repositories.

The incident is part of a broader cyber-campaign known as “Mini Shai-Hulud.” This campaign uses compromised developer tools to distribute malware across multiple technology organizations. The attack vector involved pushing 84 malicious package versions to the TanStack library within a six-minute window. 

These packages embedded an information-stealing malware designed to extract local credentials. Two OpenAI employees downloaded the corrupted package onto their devices. As a result, the hackers gained unauthorized access to a limited subset of internal source-code repositories. The attackers exfiltrated limited credentialed data. They also exposed the digital code-signing certificates used to verify OpenAI software.

A prior attack on TanStack, a well-known open-source framework that aids developers in creating web applications, compromised the devices of staff, according to a source from OpenAI.

TanStack had revealed the attack and released a postmortem on Monday, where it claimed that during a six-minute period, hackers released 84 malicious copies of its software. According to the initiative, a researcher found the attack in less than twenty minutes. The malicious TanStack versions contained malware that was intended to self-propagate to spread to other systems and steal login credentials from computers on which the program was installed.

Also worth reading
Former OpenAI Product Chief Eyes $750M AI Science Startup OpenAI Gives Vetted Defenders GPT-5.6-Cyber OpenAI Slows Astra After Critical Cyber Warning OpenAI Device Leak Sharpens The Apple Hardware Fight OpenAI Built GPT-Red To Attack Its Own Models Before Prompt Hackers Do AI Has A Sandbox Problem, Not Just A Model Problem

OpenAI claimed that it discovered credentials theft and unauthorized access “in a limited subset of internal source code repositories to which the two impacted employees had access.”

The AI giant claims that “only limited credential material” was extracted from the impacted code repositories. OpenAI stated that it is rotating the digital certificates “as a precaution,” which will require macOS users to update the program, because the impacted repositories held digital certificates used to certify OpenAI’s goods.

The business had stated that they have discovered no evidence of compromise or risk to existing software installations.

The perpetrators of the TanStack attack are unknown. A cyber gang called TeamPCP, which was also a victim of hackers, has been blamed for several of the previous supply chain breaches.

However, similar strategies have been used by other organizations against other initiatives. Axios, a well-known open-source development platform, was taken over by North Korean hackers in March, and they then distributed malware that might have affected millions of developers. Additionally, a similar attack on thousands of Windows systems running Daemon Tools, a disc imaging program, was allegedly carried out by Chinese hackers in May.

Instead of focusing on particular businesses, these attacks include hackers taking over open-source projects and releasing malware under the appearance of harmless routine updates. This enables criminals to spread the harm around the internet by possibly compromising dozens of targets with a single breach. 

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • vercel-2249343327_f343ad
    Vercel Admits To Customer Data Been Stolen Before…
  • github
    GitHub Confirms Hackers Stole Data From About 3,800…
  • handala hackers
    FBI Warns of Handala Hackers Using Telegram for Malware
  • CISA Releases Nine ICS Advisories (18) (1)
    Palo Alto Networks Data Leak Exposes Customer Details
  • Advantest_rushes_to_boost_AI_chip_tester_Bloomberg_20260128185756_Bloomberg
    Chip Tester Advantest Struck By Ransomware
  • shutterstock_chatgpt
    Researchers Warn ChatGPT Crawler May Cause DDoS…
  • 7-Eleven
    Over 185,000 Affected By 7-Eleven Data Breach
  • ORJAL4DYNFOR3K2HJT2YITAO6Q
    Meta Warns of WhatsApp Security Threat
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Artificial Intelligence Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: hackersopenaiTanStack
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Grok 4.6 Puts xAI Back In The Frontier Model Race August 13, 2026
  • Cognition’s $40B Target Shows AI Coding Is Still The Hottest Bet August 12, 2026
  • Tencent’s AI Spending Surge Shows China Has The Same Compute Problem August 12, 2026
  • Former Qwen Lead Launches Pragmatik Labs For China’s Agent Race August 12, 2026
  • Pixel Watch 5 Adds Breathing Emergency Detection As Google Pushes Health August 12, 2026
  • Pixel 11 Pro Fold Gets Brighter Screens And Real Dust Protection August 12, 2026
  • Pixel Tag Finally Gives Android A Real AirTag Rival August 12, 2026
  • Google’s Pixel 11 AI Features Show Gemini Moving Beyond Chat August 12, 2026
  • Foxconn’s AI Server Boom Is Now Bigger Than Its Apple Story August 12, 2026
  • CBN Opens Sandbox For Nigeria’s Virtual Asset And Fintech Firms August 12, 2026
  • Made By Google 2026 Is Really A Gemini Hardware Test August 12, 2026
  • Researchers Say Frontier AI Models Can Leak Hidden Reasoning August 12, 2026

Browse Archives

August 2026
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Jul    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.